CVE-2009-3303: XSS
Published Nov 24, 2009
·Updated
Cross-site scripting (XSS) vulnerability in www/help/tracker.php in GForge 4.5.14, 4.7 rc2, and 4.8.1 allows remote attackers to inject arbitrary web script or HTML via the helpname parameter.
Affected Software
3 affected components
GForge=4.7-rc2
GForge=4.8.1
GForge=4.5.14
Remediation
Patch Available
Patch Available
Event History
Nov 24, 2009
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2009-3303?
CVE-2009-3303 is classified as a medium severity cross-site scripting (XSS) vulnerability.
2
How do I fix CVE-2009-3303?
To fix CVE-2009-3303, update GForge to a version that addresses this vulnerability, preferably 4.8.1 or later.
3
Which versions of GForge are affected by CVE-2009-3303?
CVE-2009-3303 affects GForge versions 4.5.14, 4.7 rc2, and 4.8.1.
4
What type of vulnerability is CVE-2009-3303?
CVE-2009-3303 is a cross-site scripting (XSS) vulnerability that allows arbitrary web script or HTML injection.
5
Can CVE-2009-3303 be exploited remotely?
Yes, CVE-2009-3303 can be exploited remotely by attackers using the helpname parameter.